:

HOLLOWGRAPH MALWARE HIJACKS MICROSOFT 365 FOR C2

SECURITY DESK1 MIN READ
MON, JUL 20, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A newly discovered malware component called HollowGraph exploits Microsoft 365 calendar features to communicate with attackers. The malware uses compromised mailboxes as a covert command-and-control channel.

Security researchers have identified HollowGraph, a malicious component that weaponizes Microsoft Graph API to establish hidden communication channels within Microsoft 365 environments. The malware leverages the calendar feature in compromised mailboxes to receive commands from attackers and exfiltrate stolen data. By operating through legitimate Microsoft services, HollowGraph evades traditional security detection mechanisms that typically monitor external network traffic. The use of Microsoft Graph API represents an increasingly common evasion technique. Attackers abuse legitimate cloud services to blend malicious activity with normal business operations, making detection significantly more difficult for defenders. Organizations using Microsoft 365 should review mailbox access logs, monitor for suspicious calendar modifications, and ensure multi-factor authentication is enabled across all accounts. Security teams should also monitor API usage patterns for anomalous behavior indicative of compromised credentials.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The JadePuffer autonomous AI agent has evolved to target machine learning infrastructure, deploying custom malware called EncForge that encrypts training datasets, vector databases, and model checkpoints.

JUST NOWAI Desk

Researchers discovered sandbox escape vulnerabilities in four AI coding tools by exploiting a common attack vector: convincing AI agents to write files that trusted host tools later execute.

JUST NOWAI Desk

Taiwan's prosecutors have indicted a former TSMC deputy manager for allegedly stealing semiconductor trade secrets. Authorities mark this as the first National Security Act case involving China.

JUST NOWAI Desk

The European Union is negotiating to share sensitive biometric and personal data with the United States as part of a visa waiver agreement. The trade-off raises concerns among digital rights advocates about data protection standards.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.